A Perfect Copy of a Trusted Website Delivered Three Chained Zero-Days
The fake site looked convincing because most of it was real. It loaded content from the organisation it impersonated, then added one invisible frame containing two Chrome exploits, a Windows privilege-escalation exploit and a new backdoor.
Volexity says a Chinese threat actor it tracks as UTA0565 used the chain on 3 and 4 September while the vulnerabilities were still unpatched. The targets included Asian government organisations and recipients of a message impersonating the Center for American Progress.
The exploit kit had already moved between actors
The hidden frame carried exploitation for CVE-2026-85046 and CVE-2026-87491 in Chrome, followed by CVE-2026-85880 in Windows. Volexity had already reported two different Chinese groups using the same core chain. The later campaign shows a third actor adapting the delivery around cloned websites.
That does not prove the groups are one organisation. Volexity assesses that the kit was probably shared, customised and weaponised within the wider Chinese cyber-espionage community.
The final payload was built to look like browser maintenance
The page downloaded a file named chrome_cleanup.exe, removed its Mark of the Web and launched it through the Windows shell. Volexity calls the previously undocumented malware CLEANGULP.
CLEANGULP installs under a Microsoft IME-themed path, creates a scheduled task and supports command execution, process listing, file upload, file download and beacon-object-file execution. Its command traffic uses HTTP, but the body is encrypted and Base64 encoded with a custom alphabet.
What defenders should look for now
- Confirm managed Chrome and Windows systems have the fixes for all three vulnerabilities, not only the browser update.
- Search email and proxy logs for the reported typosquatted domains and related infrastructure.
- Hunt for
chrome_cleanup.exe, theMicrosoftIMEscheduled task and unexpected execution from the reported local application-data path. - Inspect pages that load most content from a legitimate domain while adding hidden local frames or scripts.
- Treat a browser crash or update prompt during a targeted visit as a possible exploitation signal.
The patches have closed the reported holes. The delivery lesson survives them: a cloned site does not need to reproduce every page perfectly when it can quietly borrow the original and hide the dangerous part where the visitor never looks.
Sources
- Volexity threat report, published 21 September 2026.
- Volexity indicators and supporting intelligence.


